Malware

What is “Win32/Kryptik.HMFZ”?

Malware Removal

The Win32/Kryptik.HMFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMFZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Win32/Kryptik.HMFZ?


File Info:

crc32: C882633B
md5: 72e7c39c1be42ae6de7fd0f1f5d76567
name: 72E7C39C1BE42AE6DE7FD0F1F5D76567.mlw
sha1: b123b67dac6862cf028eb1fa6716b180b6480ce3
sha256: cbb0fe7bfdb3ea7f08a2c55becd1d442c11b790d02e57518657a3fe6065ba92e
sha512: 6f98502252cf041a6e6b151840ceee4a967f0be6541e5a106fd77d0bfd636698bc52cab8220360202ed3f126b1151d5a3a47f72829e27241d45343015a5d1d56
ssdeep: 6144:EEnh7621TOntR+/+OJctVAtenk+Sgy3zwEokAWoQcOLQOldbq1TCcDCtHwhZU9s:Ehb7I+rtPkzjb1fovzIVqdC/tec
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.aci
ProductVersion: 7.59.25.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Win32/Kryptik.HMFZ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Win32.Convagent.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.33641
CynetMalicious (score: 100)
ALYacGen:Variant.Fragtor.12051
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Azorult.2d00aafb
K7GWTrojan ( 005690681 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFZ
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Generic-9888554-0
KasperskyHEUR:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Fragtor.12051
MicroWorld-eScanGen:Variant.Fragtor.12051
TencentWin32.Backdoor.Convagent.Aisd
Ad-AwareGen:Variant.Fragtor.12051
SophosMal/Generic-R + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34110.Cq0@aGiVHPlG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
FireEyeGeneric.mg.72e7c39c1be42ae6
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
MicrosoftTrojan:Win32/Azorult.RF!MTB
GridinsoftRansom.Win32.STOP.ko!se64491
GDataGen:Variant.Fragtor.12051
AhnLab-V3Infostealer/Win.SmokeLoader.R439001
Acronissuspicious
McAfeeGenericRXAA-AA!72E7C39C1BE4
MAXmalware (ai score=83)
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DB8F!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMFZ?

Win32/Kryptik.HMFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment